CVE-2024-24578
RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple issues within the Java based `HMIPServer.jar` component. RaspberryMatric includes a Java based `HMIPServer`, that can be accessed through URLs starting with `/pages/jpages`. The `FirmwareController` class does however not perform any session id checks, thus this feature can be accessed without a valid session. Due to this issue, attackers can gain remote code execution as root user, allowing a full system compromise. Version 3.75.6.20240316 contains a patch.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 8.74%
- CWE
- CWE-23, CWE-306
- Published
- 2024-03-18
- Last modified
- 2026-03-13
Affected products
- jens-maus RaspberryMatic
Weakness type
Related vulnerabilities
- CVE-2026-79728 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87747 — Ragic|Enterprise Cloud Database - Arbitrary File Read
- CVE-2026-47680 — Source controller: Improper path handling allows traversal
- CVE-2026-77897 — Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
- CVE-2026-72948 — Windows DNS Elevation of Privilege Vulnerability
- CVE-2026-67367 — A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE...
- CVE-2026-80130 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-80133 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...